The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.
History

Wed, 26 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Xtooltech
Xtooltech anyscan
Vendors & Products Google
Google android
Xtooltech
Xtooltech anyscan

Mon, 24 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-494
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 17:00:00 +0000

Type Values Removed Values Added
Description The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-11-24T00:00:00.000Z

Updated: 2025-11-24T18:08:57.659Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63434

cve-icon Vulnrichment

Updated: 2025-11-24T18:08:51.520Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-24T17:16:08.047

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-63434

cve-icon Redhat

No data.